Italian DPA Fines Employer for Unlawfully Accessing Former Employee's Locker
A company was fined €6,600 by the Italian Garante for opening and emptying a former employee's locker without their knowledge or consent, which was ruled a form of personal data processing under GDPR. The violation stemmed from a failure to apply core GDPR principles — transparency, fairness, and data minimization — in an employment context. Employers often underestimate that physical actions involving personal belongings or spaces can constitute data processing under European law. This case highlights that GDPR obligations extend beyond digital systems and that 'legitimate interest' cannot be freely invoked to override employee rights without a proportionate justification.
Tactical Insight
Immediate actions
- Establish a formal written policy governing access to employee personal spaces (lockers, desks, devices) that complies with GDPR principles.
- Ensure any access to a departing employee's personal property is conducted with the employee present or with documented prior notice.
Long-term improvements
- Train HR and management staff on GDPR obligations in the employment context, including what constitutes 'personal data processing' beyond digital records.
- Develop offboarding procedures that include a legally reviewed checklist for handling former employee belongings, accounts, and data.
- Conduct a Data Protection Impact Assessment (DPIA) for all HR processes involving employee personal data or physical property.
Governance & accountability measures
- Appoint or consult with a Data Protection Officer (DPO) when designing HR policies that involve employee personal information.
- Document the legal basis for any data processing activity related to employees and retain records as required under GDPR Article 30.